First published: Tue Jan 21 2025(Updated: )
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Node.js |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23083 has been categorized with a significant severity level due to the potential impact on security and privacy.
To fix CVE-2025-23083, update to the latest version of Node.js that includes the security patch addressing this vulnerability.
CVE-2025-23083 affects Node.js and its functionality related to worker threads and the diagnostics_channel utility.
Yes, CVE-2025-23083 potentially allows an attacker to exploit internal workers, which could lead to remote code execution.
CVE-2025-23083 was disclosed in January 2025 as part of the Node.js security releases.